{"record":{"id":"e0f61dfb36cf2e04","repo":"dotnet/runtime","slug":"openssl-is-not-available-but-required-for-build-d","errorCode":null,"errorMessage":"OpenSSL is not available, but required for build determinism\n","messagePattern":"OpenSSL is not available, but required for build determinism\n","errorType":"console","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/coreclr/ilasm/assem.cpp","lineNumber":255,"sourceCode":"    if (m_pCeeFileGen != NULL) {\n        if (m_pCeeFile)\n            m_pCeeFileGen->DestroyCeeFile(&m_pCeeFile);\n\n        DestroyICeeFileGen(&m_pCeeFileGen);\n\n        m_pCeeFileGen = NULL;\n    }\n\n    if (FAILED(CreateICeeFileGen(&m_pCeeFileGen))) return FALSE;\n    if (FAILED(m_pCeeFileGen->CreateCeeFileEx(&m_pCeeFile,(ULONG)m_dwCeeFileFlags))) return FALSE;\n    if (FAILED(m_pCeeFileGen->GetSectionCreate(m_pCeeFile, \".il\", sdReadOnly, &m_pILSection))) return FALSE;\n    if (FAILED(m_pCeeFileGen->GetSectionCreate (m_pCeeFile, \".sdata\", sdReadWrite, &m_pGlobalDataSection))) return FALSE;\n    if (FAILED(m_pCeeFileGen->GetSectionCreate (m_pCeeFile, \".tls\", sdReadWrite, &m_pTLSSection))) return FALSE;\n\n#if !defined(_WIN32) && !defined(__APPLE__)\n    if (m_fDeterministic && !IsOpenSslAvailable())\n    {\n        fprintf(stderr, \"OpenSSL is not available, but required for build determinism\\n\");\n        return FALSE;\n    }\n#endif\n\n    m_fGeneratePDB = generatePdb;\n\n    return TRUE;\n}\n\nvoid Assembler::SetDLL(BOOL IsDll)\n{\n    HRESULT OK;\n    OK = m_pCeeFileGen->SetDllSwitch(m_pCeeFile, IsDll);\n    _ASSERTE(SUCCEEDED(OK));\n\n    m_fDLL = IsDll;\n}\n","sourceCodeStart":237,"sourceCodeEnd":273,"githubUrl":"https://github.com/dotnet/runtime/blob/60108ba66eb7d1d12f595480091b4ad80a24b172/src/coreclr/ilasm/assem.cpp#L237-L273","documentation":"Printed at src/coreclr/ilasm/assem.cpp:255 during Assembler::Init when the deterministic-build flag (-HIGHENTROPYVA/DET option) is set but OpenSSL is unavailable on non-Windows/non-Apple platforms. Deterministic builds need a stable crypto hash (SHA-256) for GUID/MVID generation, and ilasm delegates that to OpenSSL via the pal_evp APIs.","triggerScenarios":"Triggered when Assembler::Init runs with m_fDeterministic==TRUE and IsOpenSslAvailable() (CryptoNative_OpenSslAvailable) returns 0. The option is enabled via the /DET flag parsed in main.cpp:309.","commonSituations":"Building ilasm without linking the OpenSSL-based crypto shim, or running on a Linux box where libcrypto is missing/incompatible. The check only fires outside Windows and macOS (those use built-in SHA-256).","solutions":["Install a compatible OpenSSL and ensure ilasm links the pal crypto shim that exposes CryptoNative_OpenSslAvailable.","Drop the /DET (deterministic) flag if determinism is not required.","Build/run on Windows or macOS where the built-in SHA-256 path is used.","Verify that the runtime's libcrypto dependency resolves at load time (ldd on the ilasm binary)."],"exampleFix":"// before (Linux without OpenSSL)\nilasm /DET /OUT=app.dll app.il\n// after\ncoreclr_build -DCLR_ENABLE_OPENSSL=1  # rebuild ilasm with OpenSSL\n# or simply drop the flag:\nilasm /OUT=app.dll app.il","handlingStrategy":"validation","validationCode":"// Before running ilasm /DET on Linux, verify OpenSSL is loadable\n#include <dlfcn.h>\nbool openssl_available() {\n    void* h = dlopen(\"libcrypto.so\", RTLD_NOW);\n    if (!h) h = dlopen(\"libcrypto.so.3\", RTLD_NOW);\n    if (h) { dlclose(h); return true; }\n    return false;\n}\n// Only pass /DET when openssl_available() is true, or drop the flag.","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Install a compatible OpenSSL and rebuild ilasm with the pal crypto shim.","Drop the /DET flag when determinism is not required.","Use Windows or macOS where the built-in SHA-256 path applies.","Run `ldd` on ilasm to confirm libcrypto resolves."],"tags":["coreclr","ilasm","openssl","deterministic-build","crypto"],"backgroundTag":null,"analyzedSha":"60108ba66eb7d1d12f595480091b4ad80a24b172","analyzedAt":"2026-08-10T18:54:11.478Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}